WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

[Xen-users] Recipe for 'Thin Domain 0' request

To: <xen-users@xxxxxxxxxxxxxxxxxxx>
Subject: [Xen-users] Recipe for 'Thin Domain 0' request
From: "William \(Andy\) Smith" <romaq@xxxxxxxxxxxxxxxxxxxxx>
Date: Sun, 3 Apr 2005 15:49:53 -0700
Delivery-date: Sun, 03 Apr 2005 22:49:53 +0000
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <mailman.0.1112560990.16193.xen-users@xxxxxxxxxxxxxxxxxxx>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
Reply-to: romaq@xxxxxxxxxxxxxxxxxxxxx
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
Thread-index: AcU4jfFPw5iIXRm3QFyr/X+l56taDgAABC9A
I have two identical 'Enterprise Level' machines on a bastion network.

(The Internet)
       |        Host 1
  (firewall)--<
       |        Host 2
(internal net)

The Internal net is NAT'd, I have a full support development environment and
a 2.4TB raid. Host 1 and Host 2 are currently serving public IP.

What I would like to do is replace Host 1 and Host 2 with Xen Domain0's
running on an RFC 1918 network, and have those domains be as thin as
possible. I'm hoping to learn how to PXE boot the two hosts. I need as thin
as possible a Xen Domain 0 image to pass to the host coming up. The Domain 0
image (A PXE readonly image) then needs to start guest domains from readonly
images. Each domain then picks up on the portion it can write back to.

At this time, Host 1 and Host 2 have their own 600GB raided hard drives.
Once the guest domains have their readonly image, they can then mount their
write-back portion for spools, guest home directories and so on. The
write-back will be LVMs on the hosts 600G raids for the moment, with
consideration of having portions of the 2.4 TB leased to bastions and
removing the drives later.

One particularly nasty thought is to have Host 1 and Host 2 each serve
'firewall' guest domains. We have one routing IP outside of our 'public' IP
network, and our provider will allow us a second routing IP. I would need to
prove the theory that I can isolate the NIC device and its traffic from
Domain 0 and all other domains in a firewall application.

I would like assistance with a recipe that presumes a development
environment on a separate host, builds a 'minimal domain 0' host 1 and lets
me steer towards the project I describe above.

--Romaq




_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

<Prev in Thread] Current Thread [Next in Thread>